DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Don’t pay the MongoDB ransom until you check to see if it’s a scam

Posted on January 7, 2017 by Dissent

For the past week, a number of us have been watching the explosive growth of attacks on misconfigured MongoDB installations. Victor Gevers of GDI Foundation and Niall Merrigan, a Norwegian developer, have been providing yeoman service investigating the problem, making notifications, and keeping us all apprised of their findings through their Twitter accounts.

It all started scarily – but simply – enough with attackers removing files from MongoDB installations that had been left open on Port 27017.  The attackers removed files and created a replacement database with a catchy name like “CONTACTME” or “PLEASE_READ.” The ransom notes said that the attacker had preserved all the data, and the victim could recover it if they sent BTC to the specified BTC wallet in the note. Once the payment was made, the victim was to email the attacker with their IP address, at which time, their data would presumably be returned to them. If prompt payment wasn’t made, well, the data would be permanently destroyed.

It seemed like a straightforward ransom model when DataBreaches.net reported on how Emory Healthcare had apparently become one of its victims.

But things rapidly devolved.

Within days of the first attacks, one attacker (HaraK1r1)’s email account was closed. Anyone making a payment and then attempting to email HaraK1r1 to get their data back would not have been able to do so.

Then, and as other attackers joined the party, they seem to have stomped over each other’s work:

In Dec 2016 @GDI_FDN warned a 60 companies for an open MongoDB
47 were hit by harak1r1 on 1/2. On 1/5 0wn3d overwrites note on 33 of them.

— Victor Gevers (@0xDUDE) January 5, 2017

One attacker even acknowledged that this might have happened, in which case, they wrote, a partial refund would be offered.

But of greater concern, and as Victor Gevers has been trying to warn victims since January 5, most of these hackers are lying (what a shock, right?).

Gevers and Niall Merrigan are finding evidence that although the hackers claim they have saved your data and will return it, for the most part, that is not what is happening. What is happening, the researchers claim, is that the data are just being wiped. There appears to be one attacker who may be saving some of the data, but overall, this now appears to be a tremendous scam where attackers claim to have stolen your data, and if you’ll just pay them, you’ll get it back, when in reality, they’ve just deleted your data. Why should they pay for all that storage space, right, if they can get you to send them about $200 in a panic?

As of the time of this posting, there have been about 12 accounts/attackers, each with its own email address and bitcoin wallet(s), and there have been more than 11,253 MongoDB installations that have been wiped in the past few weeks.

For a listing of known attacker accounts with their corresponding email addresses, bitcoin wallets, and additional details, see this helpful document created and maintained by Gevers and Merrigan.

DataBreaches.net will continue to cover this situation.

But NOW will you take a minute to check whether your MongoDB installation is secure? If it’s not, you may wind up locking the barn door after the horse gets stolen or worse, killed. MongoDB has provided these instructions for how to avoid becoming a victim.


Related:

  • IVF provider Genea notifies patients about the cyberattack earlier this year.
  • Key figure behind major Russian-speaking cybercrime forum targeted in Ukraine
  • France Travail: At least 340,000 job seekers victims of new hack
  • Suspected XSS Forum Admin Arrested in Ukraine
  • PowerSchool commits to strengthened breach measures following engagement with the Privacy Commissioner of Canada
  • Two more entities have folded after ransomware attacks
Category: HackOf Note

Post navigation

← Waterly app potentially exposed up to 1 million Israelis’ details- researcher
Los Angeles Valley College Hit By Cyber Attack, Pays Ransom →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Federal judiciary says it is boosting security after cyberattack; researcher finds new leaks
  • Bank of America Refused To Reimburse Georgia Customer After Hackers Hit Account. Then a News Station Showed Up.
  • NCERT Issues Advisory on “Blue Locker” Ransomware Targeting Pakistan’s Key Institutions
  • Scattered Spider has a new Telegram channel to list its attacks
  • SC: Spartanburg County hit by cyberattack, some online services disrupted
  • Pakistan Petroleum thwarts ransomware attempt, says no critical data compromised
  • ShinyHunters sent Google an extortion demand; Shiny comments on current activities
  • Air France and KLM alert customers to data breach on external platform
  • Samourai CEO Keonne Rodriguez and Samourai CTO William Lonergan Hill Pled Guilty to Operating a Money Transmitting Business, Samourai Wallet, That Transmitted Over $200 Million in Criminal Proceeds
  • 6.4 million Bouygues Telecom just had their data exposed in a huge data breach – and it’s the second to hit French telecoms operators in a month

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Germany’s top court holds that police can only use spyware to investigate serious crimes
  • Flightradar24 receives reprimand for violating aircraft data privacy rights
  • Nebraska Attorney General Sues GM and OnStar Over Alleged Privacy Violations
  • Federal Court Allows Privacy Related Claims to Proceed in a Proposed Class Action Lawsuit Against Motorola
  • Italian Garante Adopts Statement on Health Data and AI
  • Trump administration is launching a new private health tracking system with Big Tech’s help
  • Attorney General James Takes Action to Protect Sensitive Personal Information of Tens of Millions of People

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.